Malicious PDF — malware analysis report

Static analysis result for SHA-256 552ca85f98fbab79…

MALICIOUS

PDF

14.3 KB Created: 2019-05-02 00:17:15 +01:00 Authoring application: mPDF 5.7
MD5: a96353b3876ee6de5b3cd4d6fd284dcb SHA-1: 699ca866f46835b794e0a499bade5a670e1195d3 SHA-256: 552ca85f98fbab7974f080dcf72f3ab9add3278ee2891859ae5dfc25dce32d3d
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious File

The PDF contains a large number of embedded URLs, identified as a link farm. The ML classifier strongly indicates maliciousness. While the URLs themselves are currently marked as benign, the sheer volume and the heuristic firing suggest a malicious intent, likely to redirect users to harmful content or for SEO manipulation. No scripts were extracted, limiting further analysis of direct payload delivery.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9891

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/6097095092091090/Calasade-Gilinard-s-Lamentation-by-Mark-Stone.pdf
    • http://loaminoo.linkpc.net/4091096092098096/Calasade-Blood-Isle-by-Mark-Stone.pdf
    • http://loaminoo.linkpc.net/4098096093090090/The-Fruit-of-Stone-by-Mark-Spragg.pdf
    • http://loaminoo.linkpc.net/1091096095094096098/The-Judas-Line-by-Mark-Everett-Stone.pdf
    • http://loaminoo.linkpc.net/5098098094092097/Flesh-And-Stone-A-Michael-Carpo-Mystery-by-Mark-Miano.pdf
    • http://loaminoo.linkpc.net/3092094097094095/Chains-of-Water-and-Stone-The-Griever-s-Mark-2-by-Katherine-Hurley.pdf
    • http://loaminoo.linkpc.net/2096099093090/Lamentation-Jay-Porter-1-by-Joe-Clifford.pdf
    • http://loaminoo.linkpc.net/6097095092098091/Lamentations-The-Five-Poems-Of-Lamentation-by-Jon-Vandermark.pdf
    • http://loaminoo.linkpc.net/6097095092098097/Lamentation-for-the-Children-by-Walter-Perrie.pdf
    • http://loaminoo.linkpc.net/3099093096095092/Lamentation-Matthew-Shardlake-6-by-C-J-Sansom.pdf
    • http://loaminoo.linkpc.net/1095096091096092/Lamentation-Psalms-of-Isaak-1-by-Ken-Scholes.pdf
    • http://loaminoo.linkpc.net/2098092097098099/The-Lamentation-of-Their-Women-by-Kai-Ashante-Wilson.pdf
    • http://loaminoo.linkpc.net/6097095090099097/The-Lamentation-of-a-Sinner-by-Katherine-Parr.pdf
    • http://loaminoo.linkpc.net/6097095090099096/A-Lamentation-of-Swans-by-Desiree-Acuna.pdf
    • http://loaminoo.linkpc.net/6097095092098096/A-Lamentation-of-Thieves-by-Lance-Hawvermale.pdf
    • http://loaminoo.linkpc.net/9098099092/Lamentation-Matthew-Shardlake-6-by-C-J-Sansom.pdf
    • http://loaminoo.linkpc.net/1093095090094099/The-Sixth-Lamentation-Father-Anselm-1-by-William-Brodrick.pdf
    • http://loaminoo.linkpc.net/3091092091092097/Book-Girl-and-the-Wayfarer-s-Lamentation-light-novel-by-Mizuki-Nomura.pdf
    • http://loaminoo.linkpc.net/9094099095090/Making-My-Own-Rainbows-Poems-of-love-life-and-lamentation-by-Chriscinthia-Blount.pdf
    • http://loaminoo.linkpc.net/9090099094094098/Lamentation-as-History-Narratives-by-Koreans-in-Japan-1965-2000-by-Melissa-Wender.pdf